← All breaking-change reports

Cloudflare API breaking change: path-removed on /system/accounts/{account_tag}/stores/{store_id}/secrets

cloudflare · breaking · 2026-07-27 · source: OpenAPI spec diff

What changed

According to the OpenAPI spec diff (cloudflare/cloudflare-oas-7abe88500e55-to-c92b9b0fde23-removals), the following surface changed:

path-removed: /system/accounts/{account_tag}/stores/{store_id}/secrets

cloudflare OAS corridor pair 7abe88500e55 -> c92b9b0fde23 (client-breaking removals subset ingested 2026-08-01)

Who is affected

Mechanical URL rewrite at every call site: requests hitting '/system/accounts/{account_tag}/stores/{store_id}/secrets' (delete, get, post) move to '/accounts/{account_id}/secrets_store/stores/{store_id}/secrets'.

To find out whether your repo is hit — file and line number, no code leaving your machine:

npx mendapi sync  # the one network call: fetch the change feed
npx mendapi scan --repo .  # local scan, nothing leaves your machine

How to fix it

mendapi ships a deterministic migration pack for this change (cloudflare-secrets-store-and-ai-security-path-renames). Preview the patch locally (dry-run is the default; nothing is modified without --apply):

npx mendapi fix --repo . --migration cloudflare-secrets-store-and-ai-security-path-renames

The pack is idempotent, gold-regression tested, and safe on partially migrated code.

What the migration does:

Mechanical URL rewrite at every call site: requests hitting '/system/accounts/{account_tag}/stores/{store_id}/secrets' (delete, get, post) move to '/accounts/{account_id}/secrets_store/stores/{store_id}/secrets'. Update raw URL builders, route constants and API client wrappers accordingly. The successor carries the identical method set in NEW; the legacy /system alias is removed. account_tag becomes account_id.

Before:

await cf.request('/system/accounts/{account_tag}/stores/{store_id}/secrets');

After:

await cf.request('/accounts/{account_id}/secrets_store/stores/{store_id}/secrets');

Replacement data source: the successor route /accounts/{account_id}/secrets_store/stores/{store_id}/secrets in the NEW spec

Detected and tracked by mendapi — Dependabot for every API you depend on. Scans run locally; your code never leaves your machine.

Related

Change data is recorded from upstream provider releases, changelogs and OpenAPI spec diffs; every article names its source.